Privacy Policy
How we process personal data when you visit this website, in accordance with the GDPR.
1. Controller
CloudXT GmbH, Werner-von-Siemens-Str. 6, 86159 Augsburg, Germany, is the controller ("we") within the meaning of the EU General Data Protection Regulation ("GDPR") for the processing of personal data described in this policy.
Managing Directors: Patrick Marwede, Raphael Pabst
Email: info@cloudxt.io
2. Overview of processing on this website
This website is deliberately lean: it does not use cookies, does not run analytics or tracking software, and does not embed third-party content such as maps, videos, or social media widgets. The only personal data processed are the server log data described in Section 3 and, if you choose to use it, the data you enter into the contact form described in Section 5.
3. Hosting and server log files
This website is hosted on Microsoft Azure Static Web Apps. Whenever you visit it, our hosting provider automatically records certain information in server log files, transmitted automatically by your browser. This typically includes:
- IP address of the requesting device
- Date and time of the request
- Browser type and version
- Operating system used
- The page requested and the page you came from (referrer URL)
- Amount of data transferred and HTTP status code
This data is processed to ensure the technical delivery of the website, to maintain IT security (e.g., to detect and defend against attacks), and to ensure stable operation. The legal basis is our legitimate interest under Art. 6(1)(f) GDPR in providing a secure, functional website. Log data is generally deleted automatically after a short period once it is no longer needed for these purposes, unless it must be retained longer as evidence in the event of an attack.
Microsoft Corporation acts as a processor for us in connection with hosting and is contractually bound under Art. 28 GDPR, including, where applicable, the EU Data Boundary and/or EU Standard Contractual Clauses for any processing outside the EU/EEA. Further information is available in Microsoft's own privacy documentation.
4. Cookies and local storage
This website does not set cookies, does not use browser local storage or session storage for tracking purposes, and does not use any analytics, advertising, or social media tracking technologies. No consent banner is displayed because none is required for the technical operation of this site.
5. Contact form
The Contact page includes a form for Name, Company, Email, and Message. This form does not submit data to our servers or to any third-party service. Instead, your browser uses the information you enter to pre-fill a new email addressed to info@cloudxt.io in your device's default email application (a "mailto" link). The data you entered is only transmitted once you actively send that email through your own email client and provider.
Because we do not receive this data until you send the email yourself, we process it the same way as any other message sent to us directly: to respond to your inquiry. The legal basis is Art. 6(1)(b) GDPR where your inquiry relates to entering into a contract, and Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries addressed to us) in all other cases. We delete this correspondence once your inquiry has been fully resolved, unless statutory retention obligations require us to keep it longer.
6. Web fonts
This website uses the typefaces Archivo, Public Sans, and Azeret Mono. These fonts are downloaded and self-hosted as part of the website itself at build time (via Next.js' built-in font optimization) rather than loaded from Google's servers at runtime. As a result, your browser does not connect to Google or any other third party to display these fonts, and no personal data is transmitted for this purpose.
7. Encryption
This website uses SSL/TLS encryption for all connections to protect confidential content — such as information you may enter into the contact form — against unauthorized access by third parties in transit. You can recognize an encrypted connection by the "https://" prefix and the lock icon in your browser's address bar.
8. Recipients of personal data / transfers to third countries
Beyond the hosting provider named in Section 3, we do not share personal data collected through this website with any third party. Where hosting infrastructure involves processing outside the European Union or European Economic Area, we rely on the safeguards referenced in Section 3, such as the EU Standard Contractual Clauses, to ensure an adequate level of data protection.
9. Your rights as a data subject
If personal data concerning you is processed, you are a data subject within the meaning of the GDPR and have the following rights against us as the controller:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on legitimate interests (Art. 21 GDPR)
- Right to withdraw consent with future effect, where processing is based on consent (Art. 7(3) GDPR)
To exercise any of these rights, please contact us using the details in Section 1.
10. Right to lodge a complaint with a supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. The supervisory authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example when we add new features to this website or when legal requirements change. The current version, as published on this page, always applies.
Last updated: 6 August 2026.
